A flaw in Node.js proxy tunnel error handling could expose proxy credentials in `ERR_PROXY_TUNNEL` error messages.
When proxy credentials are embedded in the proxy URL, they may be exposed through error handling paths and captured by logs, diagnostics, or other error consumers.
This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.
References
| Link | Resource |
|---|---|
| https://nodejs.org/en/blog/vulnerability/june-2026-security-releases | Patch Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2026-06-26 02:16
Updated : 2026-06-26 20:18
NVD link : CVE-2026-48615
Mitre link : CVE-2026-48615
CVE.ORG link : CVE-2026-48615
JSON object : View
Products Affected
nodejs
- node.js
CWE
CWE-359
Exposure of Private Personal Information to an Unauthorized Actor
